A Work Plan is a visual representation of the running playbook that is assigned to an incident. Use it to monitor and manage a playbook workflow.
The Work Plan is a visual representation of the running playbook assigned to the incident. Playbooks enable you to automate many security processes, such as managing your investigations and handling tickets. Work Plans enable you to monitor and manage a playbook workflow, and add new tasks to tailor the playbook to a specific investigation.
In an investigation, when you open the Work Plan tab you can see the playbook, the playbook name, and navigation tools.
By default, the Follow checkbox is checked, which allows you to see the playbook executing in real-time. The playbook moves when a task is completed.
In the Work Plan you can do the following:
Action | Description |
---|---|
Change the default playbook | On the left-hand side of the window, select the playbook you want to run. When changing the playbook, all completed tasks are removed and the new playbook will run. If you select playbooks several times you can view the history of which playbooks ran. |
Rerun the playbook | When changing the playbook, select the current playbook to run again. |
View inputs and outputs | View the inputs and outputs of each task that has run. You can't view inputs and outputs of any task that hasn't run. |
Manage tasks | View, create, and edit a playbook task. For each task, you can do the following:
You can manage these tasks in the CLI by using the |
Export to a PNG | Export the Work plan to a PNG format for easy analysis. |
For a phishing investigation, after the initial playbook run parses the email and extracts email addresses, as part of the manual investigation, you could use the Email Address Enrichment - Generic v2.1 playbook as an ad-hoc playbook task to get more information about these email addresses.
The color coding and symbols in the Work Plan help you to easily troubleshoot errors or respond to manual steps. The following table displays the playbook tasks and icons in the Work Plan.